Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Srimax

Srimax Vendor Cyber Rating & Cyber Score

srimax.com

Srimax is an offshore web development company, delivers in-depth solutions for small, medium and large enterprise projects, e-commerce solutions and much more. Our strong team of software professionals have expertise in PHP, Ajax, ASP.NET, Java, C# and Node.Js etc who powers the development work. With a rich and vast experience in providing offshore software development services with high quality standards, we offer the following Services. 1. Web Development 2. Application Development 3. Mobile Development 4. HTML5 Development 5. E-commerce Solutions 6. Web Designing 7. Migration Some of our world’s most useful business Products: 1. Output Messenger The fast, secure & private instant messenger designed specifically for keeping remote


Srimax A.I CyberSecurity Scoring

Srimax
Company Information
Website:https://www.srimax.com
Employees number:83
Number of followers:708
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:srimax.com
Srimax Risk Score (AI oriented)
Between 750 and 799
logo
SrimaxIT Services and IT Consulting
Updated:
09/03/2026
753/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Srimax Global Score (TPRM)
xxxx
logo
SrimaxIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Srimax
SrimaxFair
Current Score
753Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
754Before Incident
MAY 2026
753Before Incident
APRIL 2026
753Before Incident
MARCH 2026
753Before Incident
FEBRUARY 2026
753Before Incident
JANUARY 2026
753Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
753Before Incident
OCTOBER 2025
753Before Incident
SEPTEMBER 2025
753Before Incident
AUGUST 2025
753Before Incident
JULY 2025
753Before Incident
APRIL 2024
752Before Incident
Vulnerability
01 Apr 2024Srimax
Srimax and Output Messenger: Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers

Marbled Dust Exploits Zero-Day in Output Messenger for Cyber Espionage

750After Incident
CRITICAL-2
SRISRI1767087399
Marbled Dust Exploits Zero-Day in Output Messenger for Cyber Espionage Targeting Kurdish Military A Türkiye-linked threat actor, tracked as Marbled Dust (also known as Cosmic Wolf, Sea Turtle, and UNC1326), has been exploiting a zero-day vulnerability (CVE-2025-27920) in Output Messenger, an Indian enterprise communication platform, since April 2024. The campaign, uncovered by Microsoft Threat Intelligence, targeted Kurdish military entities in Iraq, aligning with the group’s historical focus on regional espionage. The flaw—a directory traversal vulnerability in Output Messenger version 2.0.62—allowed attackers to remotely execute arbitrary files. The developer, Srimax, patched the issue in December 2024 with version 2.0.63, though its advisory did not acknowledge in-the-wild exploitation. Microsoft assessed that Marbled Dust conducted reconnaissance to identify Output Messenger users before leveraging the zero-day. The attack chain began with authenticated access to the Output Messenger Server Manager, likely obtained via DNS hijacking or typosquatted domains. Once inside, the threat actor exploited CVE-2025-27920 to deploy malicious payloads, including: - OM.vbs and OMServerService.vbs (dropped in the server startup folder) - OMServerService.exe (a Golang backdoor placed in the server’s Users/public/videos directory) The backdoor communicated with a hard-coded domain (api.wordinfos[.]com) for data exfiltration. On the client side, the installer executed both the legitimate OutputMessenger.exe and a second Golang backdoor (OMClientService.exe), which connected to a Marbled Dust command-and-control (C2) server. The backdoor performed a connectivity check before sending victim hostname data, with responses executed via Windows command prompt (cmd /c). Microsoft also identified a second reflected XSS vulnerability (CVE-2025-27921) in the same version but found no evidence of its exploitation. The attack marks a shift in Marbled Dust’s sophistication, suggesting escalated targeting priorities or operational urgency while maintaining its established espionage focus. The group, active since at least 2017, has previously targeted telecoms, ISPs, IT service providers, and Kurdish entities in the Middle East, North Africa, and Europe.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Cyber Espionage
IMPACT
Data Compromised: User data, credentials, and sensitive informationSystems Affected: Output Messenger Server Manager, Output Messenger ClientOperational Impact: Data exfiltration, unauthorized access to sensitive communicationsBrand Reputation Impact: Potential reputational damage to Output MessengerIdentity Theft Risk: High (PII exposure)
DATA BREACH
Type Of Data Compromised: User credentials, communication data, personally identifiable information (PII)Sensitivity Of Data: High (military-related, PII)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Srimax ?
?
What was Srimax's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Srimax's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Srimax's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Srimax's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Srimax's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Srimax's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Srimax's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Srimax's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Srimax's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Srimax's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Srimax's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Srimax's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Srimax ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Srimax's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?